0 Members and 1 Guest are viewing this topic.
1. But if it's the interaction between rundll32 and ctfxwlauncher that is suspicious, then reporting ctfxwlauncher as FP could be misleading, couldn't it?2. I think I'll rather do some more investigation before.
Thanks for your quick reply and the explanation.I've already tested the file on virustotal before. Here's the result:https://www.virustotal.com/de/file/4b74e3aa3ade083f03984e87f8d67da72d9a7bbaaacef23dd1dd28dcfcd14dca/analysis/1424096044/Rundll32 is also clean.I'll have to check what it is executing next time the issue appears. Maybe some explorer plugin or the like.Alex